Zero Day Monitor
ZDM
Dashboard
Vulnerabilities
Trending
Zero-Days
News
About
Login
All types
CVE only
Pre-CVE only
CISA KEV only
All severities
Critical
High
Medium
Low
More filters
Trending
Newest
Urgent
Critical Only
Weekly Urgent
Weekly Trending
182,596 vulnerabilities total
9.8
jetbrains ·
CVE-2026-63077 —
CVE-2026-63077: In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent pollin
KEV
EXPLOITED
PATCHED
teamcity
· CVSS 9.8
· CWE-502
134
🔥
11 art.
0
Jul 27, 2026
7.8
trueconf ·
CVE-2026-3502 —
TrueConf Client Update Integrity Verification Bypass
KEV
EXPLOITED
trueconf
· CVSS 7.8
· CWE-494
133
🔥
8 art.
1
Mar 30, 2026
9.8
microsoft ·
CVE-2026-50522 —
Microsoft SharePoint Remote Code Execution Vulnerability
KEV
EXPLOITED
PATCHED
sharepoint_server
· CVSS 9.8
· CWE-502
128
🔥
11 art.
0
Jul 14, 2026
5.3
microsoft ·
CVE-2026-56164 —
Microsoft SharePoint Server Elevation of Privilege Vulnerability
KEV
EXPLOITED
PATCHED
sharepoint_server
· CVSS 5.3
· CWE-306
127
🔥
21 art.
0
Jul 14, 2026
7.8
linux ·
CVE-2026-31431 —
crypto: algif_aead - Revert to operating out-of-place
KEV
EXPLOITED
PATCHED
linux_kernel
· CVSS 7.8
124
🔥
89 art.
0
Apr 22, 2026
9.6
progress ·
CVE-2026-8037 —
OS Command Injection Remote Code Execution Vulnerability in Progress LoadMaster, ECS Connection Manager, Object Scale Connection Manager & MOVEit WAF
KEV
EXPLOITED
PATCHED
connection_manager_for_objectscale
· CVSS 9.6
· CWE-77
124
🔥
9 art.
0
Jun 4, 2026
9.8
langflow ·
CVE-2026-9198 —
Unauthenticated Remote Code Execution via Auto-Login Bypass and Code Validation
KEV
EXPLOITED
PATCHED
langflow
· CVSS 9.8
· CWE-94
123
🔥
6 art.
0
Jul 17, 2026
8.8
apache ·
CVE-2026-34197 —
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could perform RCE via Jolokia MBeans
KEV
EXPLOITED
PATCHED
activemq
· CVSS 8.8
· CWE-20
118
🔥
23 art.
0
Apr 7, 2026
9.8
langflow ·
CVE-2026-0770 —
Langflow exec_globals Inclusion of Functionality from Untrusted Control Sphere Remote Code Execution Vulnerability
KEV
EXPLOITED
langflow
· CVSS 9.8
· CWE-829
90
5 art.
0
Jan 23, 2026
9.3
checkpoint ·
CVE-2026-50751 —
User Authentication Bypass in VPN Remote Access and Mobile Access
KEV
EXPLOITED
PATCHED
gaia_os
· CVSS 9.3
· CWE-287
88
23 art.
0
Jun 8, 2026
8.5
red hat ·
CVE-2026-4480 —
Samba: samba: remote code execution in printing subsystem via unescaped job description
KEV
EXPLOITED
PATCHED
openshift_container_platform
· CVSS 8.5
· CWE-78
80
5 art.
0
May 26, 2026
7.5
apache ·
CVE-2026-34486 —
Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
EXPLOITED
PATCHED
tomcat
· CVSS 7.5
· CWE-311
78
10 art.
0
Apr 9, 2026
6.1
alinto sogo ·
CVE-2026-8496 —
A cross-site scripting (XSS) vulnerability in Alinto SOGo, version 5.12.7
KEV
EXPLOITED
PATCHED
sogo
· CVSS 6.1
· CWE-79
75
2 art.
0
May 13, 2026
9.8
exim ·
CVE-2026-45185 —
CVE-2026-45185: Exim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing p
EXPLOITED
PATCHED
exim
· CVSS 9.8
· EPSS 0.01
· CWE-416
74
7 art.
0
May 12, 2026
10.0
arista ·
CVE-2026-16812 —
VeloCloud Orchestrator OS Command Injection
PATCHED
velocloud_orchestrator
· CVSS 10.0
· CWE-78
73
8 art.
0
Jul 27, 2026
8.8
linux ·
CVE-2026-53359 —
KVM: x86: Fix shadow paging use-after-free due to unexpected role
EXPLOITED
PATCHED
linux_kernel
· CVSS 8.8
72
20 art.
0
Jul 4, 2026
7.8
linux ·
CVE-2026-46331 —
net/sched: fix pedit partial COW leading to page cache corruption
EXPLOITED
PATCHED
linux_kernel
· CVSS 7.8
72
16 art.
0
Jun 16, 2026
8.1
microsoft ·
CVE-2026-42897 —
Microsoft Exchange Server Spoofing Vulnerability
KEV
EXPLOITED
PATCHED
exchange_server
· CVSS 8.1
· CWE-79
71
30 art.
0
May 14, 2026
7.1
apple ·
CVE-2026-65400 —
CVE-2026-65400: An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS
EXPLOITED
PATCHED
macos
· CVSS 7.1
· CWE-20
70
6 art.
0
Aug 6, 2026
9.9
n8n ·
CVE-2025-68613 —
n8n is an open source workflow automation platform. Versions starting with 0.211.0 and prior to 1.120.4, 1.121.1, and 1.122.0 contain a critical Remote Code Execution (RCE) vulnerability in their work
KEV
EXPLOITED
PATCHED
n8n
· CVSS 9.9
· CWE-913
70
7 art.
0
Dec 19, 2025
Load more